Cloudflare patches cross-tenant flaw in Containers and Sandboxes
The fix closes a route that could have let one customer recover another account’s residual data.
Cloudflare patched a cross-tenant flaw affecting Containers and Sandboxes that could let a Workers Paid customer retrieve remnants left by another account on the same physical machine. The cause was shared storage reassigning 64 KiB blocks without wiping them first. During testing, remnants surfaced at 18 of 24 container placements and on 20 of 22 nodes. Cloudflare says its review found no evidence that customer data had been exposed through this method. It completed its mitigation work by September 19, 2026.
Why it matters
For customers sharing a host, the flaw meant data left behind by one account could have crossed into another account’s reach. Cloudflare says it completed mitigation and found no evidence that customer data was exposed through this method.
Signal or noise?
Does this story matter, or is it hype? Decide before you see what everyone else thinks.
Sources
- BleepingComputer